Back to skill

Security audit

网文创作流水线

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a coherent Chinese web-novel workflow, but it includes AI-detection-evasion and close style-imitation guidance that users should review before installing.

Install only if you want a Chinese web-novel production workflow and are comfortable with local project-file creation and review scripts. Avoid using the detection-evasion framing to bypass disclosure rules, and do not use the style report to imitate a living or identifiable author too closely.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents the skill as an end-to-end creative writing engine capable of producing and revising Chinese web novel content. The supplied code does not implement content generation or rewriting features. Instead, it acts as a batch QA/review utility for already-written chapters: it reads local chapter files, counts Chinese characters after stripping headings/end markers, flags missing or short chapters, and prints scoring/checklist criteria for human or agent review. This is a materially different primary purpose from the declared writing engine, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description promises an end-to-end novel-writing engine with creative generation and editing functions across ideation, outlining, chapter drafting, continuation, de-AI rewriting, and quality review. The actual code only creates a directory, a subfolder, several static planning template files, and a README. This is related to the novel-writing domain, so it is not unrelated code, but the primary behavior is much narrower: project scaffolding/initialization rather than writing-engine functionality. Therefore the description materially overstates the implemented capabilities, making this a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are extremely broad and overlap with ordinary writing requests, so the skill may activate in contexts where the user did not ask for this heavyweight workflow. Unintended activation can cause prompt hijacking of benign writing tasks, unnecessary file-oriented behavior, or insertion of rigid workflow instructions that alter model behavior without clear user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description frames the skill as a Chinese web-novel writing engine and presents its primary use entirely in Chinese, while also listing English trigger phrases, but it does not state that language choice is optional or user-controlled. This can amount to a language/locale constraint without explicit opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'when to use' section lists many broad categories but does not define when not to use the skill, which makes accidental invocation more likely. In an agent system, ambiguous activation criteria can cause the model to route unrelated requests into this skill's workflow, degrading reliability and potentially causing unintended file or script assumptions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The passive trigger rule matches common intent phrases like writing novels, outlines, continuation, and anti-AI wording, which are too generic for automatic loading. In a shared agent environment this can overtake normal conversation flow and apply hidden workflow constraints, increasing the risk of inappropriate activation and user-surprising behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire skill file is written as a fixed Chinese-language workflow and does not indicate that users may choose another language or locale. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly warns against plagiarism, but later instructs the user to read a 'writing style analysis report', identify the original author's characteristics, and 'strictly follow' that report. In a novel-writing skill, this creates a real risk of style imitation that can drift into derivative copying or evasion of anti-plagiarism safeguards, especially when paired with reference-work collection and platform-oriented mass production.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill file is written as mandatory Chinese-language instructions and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document instructs use of '去AI腔过滤(stop-slop-cn)' and links to a Chinese-specific filtering guide, implying a fixed Chinese-language style and locale. There is no indication that the user can choose another language or opt in to this locale-specific constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file explicitly instructs users to make generated text look less machine-produced and labels these edits as reducing AI-detection likelihood. That is guidance for evading provenance or AI-detection controls, which can facilitate academic dishonesty, spam, or deceptive content laundering even if framed as style improvement for fiction.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The '人工修改特征' section directly says the changes are meant to lower AI detection rates and then provides concrete tactics for doing so. This is stronger than generic style advice because it operationalizes evasion of detection systems, increasing the risk of misuse for deceptive publication, policy circumvention, or fraud-adjacent content laundering.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation condition '当用户说"继续直到结束"时' is a common natural-language phrase without any domain or context restriction. In a markdown skill description, this kind of broad trigger can overlap with ordinary conversation and does not specify exclusions or required context for when the skill should auto-continue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L58 requires '去AI腔过滤≥38分', which is a natural-language quality requirement tied to Chinese-language style, and the document overall is written as a prescriptive workflow without any user opt-in or alternative language option. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The report explicitly says the output should '降低 AI 检测率' by imitating an author's style, which promotes concealment of AI authorship rather than ordinary writing assistance. In a novel-writing skill, this increases the likelihood of deceptive use, including undisclosed AI ghostwriting and style mimicry that may cross ethical or platform-policy boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's natural-language interface is entirely in Chinese, including the module description, help text, error messages, and review checklist output. Under the policy, forcing a specific language without user opt-in or a documented justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This is a plain-text file, so vague-trigger review applies. The phrase '触发:异常情绪波动(他人)' describes activation based on others' abnormal emotional fluctuation, which is broad and underspecified; it does not define thresholds, exclusions, or when the trigger should not fire.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill file is written as a Chinese-only template and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the skill offers alternative languages or that it is intentionally restricted to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire template, headings, and workflow instructions are written exclusively in Chinese, and the file does not indicate that language choice is optional or user-selectable. Under the policy rule for language or locale constraints, this is a natural-language policy concern because the skill appears to enforce a specific language without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.